
hacktronian
Tools for Pentesting

Tools for Pentesting

Exploit for WebSocket Vulnerability in Apache Tomcat

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

PoC CVE-2020-6308

Quicky serve files over http or https using flask.

CVE-2026-23631 (DarkReplica) Redis Exploit


一个验证对CVE-2024-21733


PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing…

Check list of URLs against Log4j vulnerability CVE-2021-44228

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Haraj Script 3.7 - Post Ads Authenticated Stored XSS

Mezzanine CMS 6.1.0 XSS (CVE-2025-50481)